LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
LA-Studio Element Kit for Elementor
Minimum safe version
1.6.0
Update to 1.6.0 or later to address 18 fixable vulnerabilities
CVE-2026-24947
LA-Studio Element Kit for Elementor <= 1.5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter
LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets
LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget
CVE-2025-32194
CVE-2024-10787
CVE-2024-10873
CVE-2024-47628
CVE-2024-43210
CVE-2024-37479
CVE-2024-5349
CVE-2024-35725
CVE-2024-4431
WordPress LA-Studio Element Kit for Elementor Plugin <= 1.3.7.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-2249
WordPress LA-Studio Element Kit for Elementor Plugin <= 1.1.5 is vulnerable to Broken Access Control